---
name: framework-financial-services-controls-ac-4.5
title: AC-4 (5) -  Embedded Data Types
description: 'Enforce _[Assignment: organization-defined limitations]_ on embedding data types within other data types.'
last-updated: 2025-02-27
---

> ## Documentation Index
> The table of contents for this documentation set is at https://cloud.ibm.com/docs/framework-financial-services-controls?format=markdown
> The index for all IBM Cloud docs is at: https://cloud.ibm.com/docs/llms.txt
> Use these files to discover more information as needed.

# AC-4 (5) -  Embedded Data Types
{: #ac-4.5}

## Control requirements
{: #control-requirements}



### AC-4 (5) - 0


Enforce _[Assignment: organization-defined limitations]_ on embedding data types within other data types.






## Additional IBM Cloud for Financial Services specifications
{: #additional-ibm-cloud-for-financial-services-specifications}

This control is required for ISVs.







## NIST supplemental guidance
{: #nist-supplemental-guidance}

Embedding data types within other data types may result in reduced flow control effectiveness. Data type embedding includes inserting files as objects within other files and using compressed or archived data types that may include multiple embedded data types. Limitations on data type embedding consider the levels of embedding and prohibit levels of data type embedding that are beyond the capability of the inspection tools.